Lucene search

K
ibmIBM77F340CE7E2EEA89B8061722DAF1A6DD33D7C06C7F71CBD1C709E54CF747BE67
HistoryJan 18, 2024 - 9:30 p.m.

Security Bulletin: IBM Maximo Spatial Asset Management is vulnerable to Blind Server-Side Request Forgery (CVE-2023-32337)

2024-01-1821:30:03
www.ibm.com
12
ibm maximo asset management
blind server-side request forgery
ssrf
vulnerability
fix pack
interim fix

AI Score

6.2

Confidence

High

EPSS

0

Percentile

13.1%

Summary

IBM Maximo Spatial Asset Management is vulnerable to Blind Server-Side Request Forgery

Vulnerability Details

CVEID:CVE-2023-32337
**DESCRIPTION:**IBM Maximo Spatial Asset Management is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
CVSS Base score: 5.4
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/255288 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

This vulnerability affects the following versions of the IBM Maximo Asset Management core product. The recommended action is to update to the latest version.

Affected Product(s) Version(s)
IBM Maximo Spatial Asset Management 7.6.1.0
IBM Maximo Spatial Asset Management 7.6.1.1
  • To determine the core product version, log in and view System Information. The core product version is the β€œTivoli’s process automation engine” version. Please consult the Platform Matrix for a list of supported product combinations.

Remediation/Fixes

The recommended solution is to download the appropriate Interim Fix or Fix Pack from Fix Central and apply for each affected product as soon as possible. Please see below for information on the fixes available for each product, version, and release. Follow the installation instructions in the β€˜readme’ documentation provided with each fix pack or interim fix.

For IBM Maximo Spatial Asset Management in Maximo Asset Management 7.6:

VRM Maximo Asset Management Fix Pack, Feature Pack, or Interim Fix IBM Maximo Spatial Asset Management Fix Pack, Feature Pack, or Interim Fix Download
7.6.1.2

Maximo Asset Management 7.6.1.2 iFix:
7.6.1.2-TIV-MBS-IFI039 or latest Interim Fix available

|

IBM Maximo Spatial Asset Management iFix: 7.6.1.0-TIV-MAMST-IF027 or latest Interim Fix available

| FixCentral
7.6.1.3|

Maximo Asset Management 7.6.1.3 iFix:

7.6.1.3-TIV-MBS-IF012 or latest Interim Fix available

|

IBM Maximo Spatial Asset Management iFix: 7.6.1.1-TIV-MAMST-IF010 or latest Interim Fix available

|

FixCentral

Workarounds and Mitigations

None

AI Score

6.2

Confidence

High

EPSS

0

Percentile

13.1%

Related for 77F340CE7E2EEA89B8061722DAF1A6DD33D7C06C7F71CBD1C709E54CF747BE67